IBM Support

IT34346: THE OVERRIDEDEFAULTTLS JVM SETTING ISN'T HONOURED FOR SOAPREQUEST AND HTTPREQUEST NODES

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • The JVM override com.ibm.jsse2.overrideDefaultTLS=true doesn't
    work for oubound request nodes like HTTPRequest or SOAPRequest.
    The Protocol setting on the node is used instead.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All Users of IBM Integration Bus V10 and App Connect Enterprise
    V11 with JVM option <span style="background-color:rgb(255, 255,
    255)">com.ibm.jsse2.overrideDefaultTLS</span>
    
    
    Platforms affected:
    z/OS, MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    SOAPRequest and HTTPRequest nodes have 'TLS'  as the default
    protocol value. This is equivalent to using the TLSv1.0
    protocol. However, the JVM property <span
    style="background-color:rgb(255, 255,
    255)">com.ibm.jsse2.overrideDefaultTLS=true can change it to use
    TLSv1.2 protocol. So if a customer has deployed SOAP/HTTP
    request nodes in an integration server with the default settings
    (ie. 'TLS' as the protocol value in node property), they may
    want every Request nodes to start using TLSv1.2 protocol by
    setting the overrideDefaultTLS property as below
    
    mqsichangeproperties NODE -e SERVER -o ComIbmJVMManager -n
    </span>jvmSystemProperty -v  -D<span
    style="background-color:rgb(255, 255,
    255)">com.ibm.jsse2.overrideDefaultTLS=true </span>
    
    <span style="background-color:rgb(255, 255, 255)">However, the
    setting is  not taken effect  and the Request nodes continue to
    use TLSv1.0 </span>
    

Problem conclusion

  • <span style="background-color:rgb(255, 255,
    255)">com.ibm.jsse2.overrideDefaultTLS=true </span> setting is
    picked correctly and changes the behavior of all SOAP/HTTP
    Request nodes using default 'TLS' protocol to start using
    TLSv1.2 protocol.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v10.0      10.0.0.23
    v11.0      11.0.0.11
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT34346

  • Reported component name

    INTEGRATION BUS

  • Reported component ID

    5724J0540

  • Reported release

    A00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-09-24

  • Closed date

    2020-12-15

  • Last modified date

    2020-12-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    INTEGRATION BUS

  • Fixed component ID

    5724J0540

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSNQK6","label":"IBM Integration Bus"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0"}]

Document Information

Modified date:
16 December 2020